Elastic high stable eql
Unusual Child Process from a System Virtual Process
Identifies a suspicious child process of the Windows virtual system process, which could indicate code injection.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.parent.pid == 4 and process.executable : "?*" and
not process.executable : ("Registry", "MemCompression", "?:\\Windows\\System32\\smss.exe", "HotPatch") Field Validations
Loading…
Comments (0)
Loading comments...